6.7

Table Of Contents
Table 1315. Host Configuration Privileges (Continued)
Privilege Name Description Required On
Host.Configuration.Change date
and time settings
Allows changes to date and time settings on the host. Hosts
Host.Configuration.Change
settings
Allows setting of lockdown mode on ESXi hosts. Hosts
Host.Configuration.Connection Allows changes to the connection status of a host
(connected or disconnected).
Hosts
Host.Configuration.Firmware Allows updates to the ESXi host's firmware. Hosts
Host.Configuration.Hyperthreadin
g
Allows enabling and disabling hyperthreading in a host CPU
scheduler.
Hosts
Host.Configuration.Image
configuration
Allows changes to the image associated with a host.
Host.Configuration.Maintenance Allows putting the host in and out of maintenance mode and
shutting down and restarting the host.
Hosts
Host.Configuration.Memory
configuration
Allows modifications to the host configuration. Hosts
Host.Configuration.Network
configuration
Allows configuration of network, firewall, and vMotion
network.
Hosts
Host.Configuration.Power Allows configuration of host power management settings. Hosts
Host.Configuration.Query patch Allows querying for installable patches and installing patches
on the host.
Hosts
Host.Configuration.Security
profile and firewall
Allows configuration of Internet services, such as SSH,
Telnet, SNMP, and of the host firewall.
Hosts
Host.Configuration.Storage
partition configuration
Allows VMFS datastore and diagnostic partition
management. Users with this privilege can scan for new
storage devices and manage iSCSI.
Hosts
Host.Configuration.System
Management
Allows extensions to manipulate the file system on the host. Hosts
Host.Configuration.System
resources
Allows updates to the configuration of the system resource
hierarchy.
Hosts
Host.Configuration.Virtual
machine autostart configuration
Allows changes to the auto-start and auto-stop order of
virtual machines on a single host.
Hosts
Host Inventory
Host inventory privileges control adding hosts to the inventory, adding hosts to clusters, and moving hosts
in the inventory.
The table describes the privileges required to add and move hosts and clusters in the inventory.
You can set this privilege at different levels in the hierarchy. For example, if you set a privilege at the
folder level, you can propagate the privilege to one or more objects within the folder. The object listed in
the Required On column must have the privilege set, either directly or inherited.
vSphere Security
VMware, Inc. 253